Skip to main content

Versitygw

@dataverket/versitygwv2026.10.05.1· 1d agoMODELS
01README

A versitygw S3 gateway for swamp, read over its admin API and its S3 API. Read-only. One model type, @dataverket/versitygw/gateway. health checks the S3 endpoint's health path: reachable, TLS verified, latency. accounts lists every account with its role and POSIX ids, and drops the secret key the admin API returns in clear before anything is recorded. buckets lists every bucket and its owner. bucketSettings reads each bucket's versioning, policy, ACL, object lock, ownership controls, CORS and tags over the S3 API. inventory does all of that in one execution and tags every record with one id, and check applies rules to the records of one inventory: bucket owner missing or not the account of the same name, an account owning nothing, a role outside the allowed set, versioning without object lock, lock without versioning, a default retention mode outside the allowed set, a bucket anyone may read. The same type reads a Ceph radosgw through its admin ops API (backend: rgw) or any S3 endpoint with one key pair (backend: s3); the bucket settings and the rules over them are plain S3 and the same everywhere. versitygw has no read-only admin role, so every admin call signs with the root key pair, from exactly one source: a file of NAME=value lines read at call time, swamp's environment, or the pair as values from vault expressions, so the definition stores only the reference. Signing is SigV4 by aws4fetch; errors are the gateway's S3 error codes. Written against versitygw v1.8.0.

02Models1
@dataverket/versitygw/gatewayv2026.10.05.1gateway.ts

Global Arguments

ArgumentTypeDescription
backendenumversitygw: accounts and buckets over its admin API. rgw: a Ceph radosgw, accounts and buckets over the
adminUrlstringBase URL of the admin API, e.g. http://localhost:7071, or http://host:8000/admin for rgw. May end in a path prefix. Not used by the s3 backend
s3UrlstringBase URL of the S3 API, e.g. https://s3.example.org:443
regionstringThe region the gateway was started with; it rejects any other
caFile?stringPEM file of the CA that signed the gateway's certificate, when it is not in the system store; a relative path is taken from the repository root
healthPathstringThe path given to versitygw's --health option. Other backends have none: give / and the answer counts
rootKeyFile?stringFile of NAME=value lines holding the root key pair, read at call time.
rootKeyEnvbooleanRead the root key pair from swamp's environment, e.g. under a secret
rootAccessKey?stringThe root access key as a value, e.g. ${{ vault.get("<vault>", "<key>") }};
rootSecretKey?stringThe root secret key as a value, supplied like rootAccessKey and always with it
accessKeyNamestringVariable holding the root access key, in the file or the environment
secretKeyNamestringVariable holding the root secret key, in the file or the environment
fn health()
GET the health path on the S3 port, unsigned: reachable, TLS verified, latency. Read-only.
fn accounts()
List every account but root over the admin API; each record drops the secret key. Read-only.
fn buckets()
List every bucket and its owner over the admin API. Read-only.
fn bucketSettings(buckets?: array)
Read each bucket's settings over the S3 API as root: versioning, policy, ACL, object lock, ownership controls, CORS, tags. Read-only.
ArgumentTypeDescription
buckets?arrayBuckets to read; every bucket on the gateway when omitted
fn inventory()
Health, accounts, buckets and every bucket's settings in one execution, each record tagged with this inventory's id. Read-only.
fn check(inventoryId?: string, rules: array, allowedRoles: array, allowedLockModes: array, failOnFindings: boolean)
Apply the rules to the records of one inventory and record the findings. Reads only that inventory's records; calls no API.
ArgumentTypeDescription
inventoryId?stringThe inventory to check; the latest inventory record's id when omitted
rulesarrayRules to apply. By default every rule but versioning-enabled, which a gateway meant to hold no versioned
allowedRolesarrayAccount roles the account-role rule accepts
allowedLockModesarrayDefault retention modes the lock-mode rule accepts. COMPLIANCE can be shortened by nobody until it
failOnFindingsbooleanFail the method, after recording the result, when anything is found

Resources

health(infinite)— Whether the S3 endpoint answers, over a verified chain, and how fast
account(infinite)— One account: access key, role and POSIX ids. Never its secret
bucket(infinite)— One bucket and the account that owns it
bucketSettings(infinite)— One bucket's versioning, policy, ACL, object lock, ownership controls, CORS and tags
inventory(infinite)— One inventory: its id, which tags every record it wrote, and counts
check(infinite)— What check found in one inventory
03Previous Versions3
2026.09.30.3
2026.09.30.2
2026.09.30.1
04Stats
A
100 / 100
Downloads
13
Archive size
71.1 KB
  • Has README or module doc2/2earned
  • README has a code example1/1earned
  • README is substantive1/1earned
  • Most symbols documented1/1earned
  • No slow types (deprecated)1/1earned
  • Dependencies pass trust audit2/2earned
  • Has description1/1earned
  • Platform support declared (or universal)2/2earned
  • License declared1/1earned
  • Verified public repository2/2earned
05Platforms
06Labels